← voltar
CVE-2026-41653

BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration

CVSS 7 HIGHEPSS 0.4%CWE-79
BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may be able to execute arbitrary JavaScript in certain circumstances in Markdown to PDF Tool. This issue has been patched in version 2.8.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
alam00000 · bentopdf

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →